it-securitynotifies AT lists.piratenpartei.de
Betreff:
Sicherheitsankündigungen
Listenarchiv
- From: Sabrina Seubert <sabrina.seubert AT otrs.com>
- To: announce AT otrs.org
- Subject: [IT-SecNots] [announce]New Security Updates for OTRS
- Date: Mon, 22 Mar 2021 09:59:39 +0100
- Archived-at: <https://lists.otrs.org/hyperkitty/list/announce AT lists.otrs.org/message/KTS6M3TLTDEWUKCQ7WKSZW3FRSWOTIGG/>
- Authentication-results: mail02.piratenpartei.de; dkim=none; spf=none (mail02.piratenpartei.de: domain of announce-bounces AT lists.otrs.org has no SPF policy when checking 135.181.4.15) smtp.mailfrom=announce-bounces AT lists.otrs.org; dmarc=none
- List-archive: <https://lists.otrs.org/hyperkitty/list/announce AT lists.otrs.org/>
- List-id: "Announcements about OTRS.org" <announce.lists.otrs.org>
Dear reader, The following security fix/es was/were made: |
|
OTRS Security Advisory 2021-08 ID: OSA-2021-08 Date: 2021-03-22 Title: FAQ articles are shown to users without permission Severity: 3.5 LOW Product: OTRS 7.0.24, and FAQ 6.0.29 Fixed in: OTRS 7.0.25 FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N References: CVE-2021-21438 |
|
OTRS Security Advisory 2021-07 ID: OSA-2021-07 Date: 2021-03-22 Title: Config Items are shown to users without permission Severity: 3.5 LOW Product: ITSMConfigurationManagement 7.0.24 and OTRSCIsInCustomerFrontend 7.0.15 Fixed in: ITSMConfigurationManagement 7.0.25 and OTRSCIsInCustomerFrontend 7.0.16 FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N References: CVE-2021-21437 |
|
OTRS Security Advisory 2021-06 ID: OSA-2021-06 Date: 2021-03-22 Title: ReDoS vulnerability in thirdparty library (jquery-validate) Severity: 5.3 MEDIUM Product: OTRS 8.0.x, OTRS 7.0.x, OTRS 6.0.x Fixed in: OTRS 8.0.12, OTRS 7.0.25 FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L References: CVE-2021-21252 |
|
Kind regards, Your OTRS release team |
|
Subscribe to the OTRS Newsletter.Read about OTRS service management solutions, product features, and interesting tips from our experts every month. Simply select your desired language.
|
|
OTRS AG Zimmersmühlenweg 11 61440 Oberursel Germany +49 6172 681988 0 |
|
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
--
_______________________________________________
announce mailing list -- announce AT lists.otrs.org
To unsubscribe send an email to announce-leave AT lists.otrs.org
To manage your subscription or browse the message archive visit:
https://lists.otrs.org/postorius/lists/announce.lists.otrs.org/
- [IT-SecNots] [announce]New Security Updates for OTRS, Sabrina Seubert, 22.03.2021
Archiv bereitgestellt durch MHonArc 2.6.24.